CVE-2017-12617

Executive Summary

Apache Tomcat versions 9.0.0.M1–9.0.0, 8.5.0–8.5.22, 8.0.0.RC1–8.0.46 and 7.0.0–7.0.81 are vulnerable when HTTP PUT is enabled (DefaultServlet readonly=false). An attacker can upload a JSP file via a crafted PUT request; the JSP is then served and executed, enabling remote code execution. The vulnerability is actively exploited in the wild (CISA KEV).


Authoritative CVE Metadata - CVSS Base Score: 8.1 (HIGH) - Published: 2017-10-04T01:29:02.120 - Last Modified: 2026-08-25T16:28:27.310

[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2022-03-25)

Original Description: When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

"We must become the change we want to see."

— Mahatma Gandhi
Source: NVD